ABB RES670 Technical Manual page 754

Relion 670 series, phasor measurement unit
Hide thumbs Also See for RES670:
Table of Contents

Advertisement

Section 21
Security
748
Changes in user management settings do not cause an IED reboot.
The PCM600 tool caches the login credentials after successful login for
15 minutes. During that time no more login will be necessary.
The successfully activation of Central Account Management will disable built-in users
or remove all local created users from PCM600.
Management of user credentials and roles is handled on the central Account
Management server e.g. SDM600 The IED employs two strategies to ensure
availability of the authentication system even if there is a problem with the network or
authentication server:
A substation can be equipped with two redundant authentication servers operating
in a hot standby mode.
If configured by the security administrator, the IED itself maintains a local replica
in the database with selected users. This database is periodically updated with data
from the server and used as fallback if none of the servers are reachable.
Note that not all users in the SDM600 server are part of the replica. There might be
users that are not assigned to any replication group. IED only replicates those users
which are part of replication group configured in the IED.
This replication can be disabled using PCM600 by the security administrator, which
means that the IED will forward login requests to the SDM600 for authorization and in
case of problems with the network users will not be able to log in to the IED.
If user replication has been disabled in a CAM-enabled IED and if
communication with SDM600 is lost, access to that IED will be denied
until communication is re-established.
All communication between the central management and the IEDs is protected using
secure communication. Customers using SDM600 are required to generate and
distribute certificates during the engineering process of the substation. These
certificates ensure mutual trust between IED and for example SDM600, FTP, PCM600
and other system.
1MRK 511 408-UUS A
Phasor measurement unit RES670 2.2 ANSI
Technical manual

Advertisement

Table of Contents
loading

Table of Contents